ATT&CKReferenceswardle evilquest partii

wardle evilquest partii

Patrick Wardle. (2020, July 3). OSX.EvilQuest Uncovered part ii: insidious capabilities. Retrieved March 21, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareThiefQuest

ThiefQuest prepends a copy of itself to the beginning of an executable file while maintaining the name of the executable.

T1041
Exfiltration Over C2 Channel
MalwareThiefQuest

ThiefQuest exfiltrates targeted file extensions in the /Users/ folder to the command and control server via unencrypted HTTP. Network packets contain a string with two pieces of information: a file path and the contents of the file in a base64 encoded string.

T1071.001
Web Protocols
MalwareThiefQuest

ThiefQuest uploads files via unencrypted HTTP.

T1105
Ingress Tool Transfer
MalwareThiefQuest

ThiefQuest can download and execute payloads in-memory or from disk.

T1106
Native API
MalwareThiefQuest

ThiefQuest uses various API to perform behaviors such as executing payloads and performing local enumeration.

T1486
Data Encrypted for Impact
MalwareThiefQuest

ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information.

T1554
Compromise Host Software Binary
MalwareThiefQuest

ThiefQuest searches through the /Users/ folder looking for executable files. For each executable, ThiefQuest prepends a copy of itself to the beginning of the file. When the file is executed, the ThiefQuest code is executed first. ThiefQuest creates a hidden file, copies the original target executable to the file, then executes the new hidden file to maintain the appearance of normal behavior.

T1620
Reflective Code Loading
MalwareThiefQuest

ThiefQuest uses various API functions such as NSCreateObjectFileImageFromMemory to load and link in-memory payloads.

T1622
Debugger Evasion
MalwareThiefQuest

ThiefQuest uses a function named is_debugging to perform anti-debugging logic. The function invokes sysctl checking the returned value of P_TRACED. ThiefQuest also calls ptrace with the PTRACE_DENY_ATTACH flag to prevent debugging.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.